GitLab User Enumeration...

- AV AC AU C I A
发布: 2024-09-01
修订: 2025-04-13

The GitLab internal API is exposed unauthenticated on GitLab. This allows the username for each SSH Key ID number to be retrieved. Users who do not have an SSH Key cannot be enumerated in this fashion. LDAP users, e.g. Active Directory users will also be returned. This issue was fixed in GitLab v7.5.0 and is present from GitLab v5.0.0.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息